Authlier

HTTP routes

Reference the routes added by Authlier's standard handler.

The examples use the default /api/auth authentication base path and /api/account account base path. Change them with Config.BasePath and Config.AccountBasePath. Authlier only registers routes for enabled features, except session routes, which are always available.

Common response rules

Successful JSON responses use Content-Type: application/json. A successful operation with nothing to return uses 204 No Content. Errors use one shape:

{"error":{"code":"invalid_request"}}

The browser adds an Origin header to its POST requests. That origin must match BaseURL or TrustedOrigins. SAML's provider callback is the exception because the identity provider posts it from another origin. Native clients using bearer mode may omit Origin.

Email and password

RouteRequestResult
POST /api/auth/sign-upemail, passwordCreates the user and usually a session
POST /api/auth/sign-inemail, passwordCreates a session or returns a TOTP challenge
POST /api/auth/change-passwordcurrentPassword, newPassword, revokeOtherSessionsReplaces the current password
POST /api/auth/set-passwordpasswordAdds a password to an authenticated account
POST /api/auth/remove-passwordcurrentPasswordRemoves the password when another sign-in method remains

Email verification and recovery

RouteRequestResult
POST /api/auth/resend-verificationemailSends a verification message and returns 202
GET /api/auth/verify-email?token=...Query token in link modeVerifies the email
POST /api/auth/verify-emailemail, code in OTP modeVerifies the email
POST /api/auth/forgot-passwordemailSends a reset message and returns 202
POST /api/auth/reset-passwordtoken, newPasswordReplaces the password and usually revokes sessions

The two message-request routes deliberately return the same public result when an email address does not belong to an account.

Sessions

RouteRequestResult
GET /api/auth/sessionSession cookie or bearer access tokenReturns the current session
POST /api/auth/sign-outCurrent credentialRevokes the current session
POST /api/auth/token/refreshrefreshToken in bearer modeRotates the refresh token and returns a new token pair
GET /api/auth/list-sessionsSession cookie or bearer access tokenReturns active sessions for the current subject
POST /api/auth/revoke-sessionsessionIdRevokes one session owned by the current subject
POST /api/auth/revoke-other-sessionsCurrent credentialRevokes the others and replaces the current session
POST /api/auth/revoke-sessionsCurrent credentialRevokes every session for the current subject

In bearer mode, authenticated routes use Authorization: Bearer <access-token>. Authentication and refresh responses include the tokens object described in Bearer tokens.

Google

RouteRequestResult
POST /api/auth/googleEmpty bodyReturns the Google authorization URL
GET /api/auth/google/callbackProvider queryValidates the callback and creates a session
POST /api/account/googleSession cookieReturns an authorization URL for account linking
DELETE /api/account/googleSession cookieRemoves the linked Google identity when another sign-in method remains

TOTP

RouteRequestResult
POST /api/auth/two-factor/totp/enableaccountNameStarts enrollment and returns the secret and URI
POST /api/auth/two-factor/totp/confirmcodeEnables TOTP and returns recovery codes
POST /api/auth/two-factor/verifychallengeToken, codeCompletes sign-in with an authenticator code
POST /api/auth/two-factor/recoverchallengeToken, codeCompletes sign-in with a recovery code
POST /api/auth/two-factor/disableSession cookieRemoves the TOTP credential

Passkeys

RouteRequestResult
POST /api/auth/passkey/register/optionsSession cookieReturns registration options and a ceremony token
POST /api/auth/passkey/register/verifyceremonyToken, responseVerifies and stores the new credential
POST /api/auth/passkey/sign-in/optionsEmpty bodyReturns assertion options and a ceremony token
POST /api/auth/passkey/sign-in/verifyceremonyToken, responseVerifies the assertion and creates a session
GET /api/auth/passkey/listSession cookieLists credential IDs
POST /api/auth/passkey/removecredentialIdRemoves a credential when another method remains

SSO

RouteRequestResult
POST /api/auth/sso/oidc/sign-inconnectionIdReturns the provider authorization URL
GET /api/auth/sso/oidc/callbackProvider queryResolves the OIDC identity and creates a session
POST /api/auth/sso/saml/sign-inconnectionIdReturns the provider authorization URL
POST /api/auth/sso/saml/callbackSAML form postResolves the SAML identity and creates a session
GET /api/auth/sso/saml/metadata?connectionId=...Connection queryReturns service-provider metadata

Error codes

Common codes include invalid_request, invalid_credentials, not_authenticated, recent_authentication_required, too_many_attempts, invalid_token, last_sign_in_method, session_not_found, and sso_connection_not_found. Feature-specific verification failures use stable codes such as passkey_verification_failed, google_authentication_failed, oidc_authentication_failed, and saml_authentication_failed.

Treat unrecognized codes as a general failure so a newer Authlier version does not break the interface.

On this page